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AMENDMENTS TO THE CLAIMS 

THIS LISTING OF CLAIMS WILL REPLACE ALL PRIOR VERSIONS, AND 
LISTINGS OF CLAIMS IN THE APPLICATION. 

1 . (Currently amended) A method for detecting spurious network traffic comprising: 

receiving a packet, the packet including data for transmission over a network; 

calculatin g a plurality of possible ports from wh ich the packet is expected to be 
received using a source network address of the packet, wherein each one of the plurality 
of possible ports has associated therewith a weight the weight relating to a likelihood 
that the packet is received from the one of the plu rality of possible ports; 

determining an expected port for the packet upon which the packet is expected to 
he receive d based on relative weights of the po ssible ports; 

determining an actual port for the packet upon which the packet is actually 
received; 

comparing the actual port to the expected port; and 

providing spurious packet handling when the actual port does not correspond to 
the expected port. 

2. Cancelled 

3. (Original) The method of claim 1 wherein spurious packet handling includes 
discarding the packet. 

4. (Original) The method of claim 1 wherein spurious packet handling includes 
generating an alert. 

5. (Original) The method of claim 1 wherein the packet comprises an Internet Protocol 
packet. 
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6. (Currently amended) The method of claim 1 wherei n dutoiiuii iing,tho oxpootrcd p ort 
for the packet calculating the plurality of possible ports further comprises: 

determining a source network address for the packet; and 

calculating** expected-pe* paths for the packet according to routing trees of 

switches in the network, wherehvaB-eadiftg endings o f the expected-path4s paths are the 

Avpoot e d po rt possible ports . 

7. (Currently amended) The method of claim 1 wherein determining an expected port for 
the packet further comprises: . 

generating a table, the table associating each one of a plurality of possible source 

network addresses with a-s wiglo port; possible port and a weight 
determining a oouroo network addroso for the pack e t ; and 
applying the table to determin e single port aooooiatod with tho oouroo network 

addroso, tho oinglo port b e ing (he expected port. 



8. (Currently amended) A system for detecting spurious network traffic comprising:- 

receiving means for receiving a packet; 

mapping means for calculating a plurality o f possible ports from which the packet 
is expected to be received using a source network address of the packet, wherein each one 
of the plurality of possible ports has associated there with a weight, the weight relating to 
a likelihood that the packet is received from the one o f the plurality of possible ports; 

first determining means for deteimining an expected port for the packet based on 
relative wei ghts of the possible ports : 

second determining means for determining an actual port for the packet; 

comparing means for comparing the expected port and the actual port; and 

handling means for providing spurious packet handling upon determining that the 
actual port does not correspond to the expected port. 

9. Cancelled 
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10. (Currently amended) A switch for use in an internetwork, the switch comprising: 
a plurality of ports, each port connected in a communicating relationship with at 

least one of a connected switch and a network; 

a touting database, the routing database containing information relating to the 

internetwork; and 

a processor; the processor configured to compare a first port of the plurality of 
ports through which a packet is received to a second port of the plurality of ports through 
which the packet is expected to be received, the processor further configured to provide 
spurious packet handling upon detennining that the first port is different from the second 
pnit, and configured to generate an expected port tab le, the expected port table mapping 
each of a plurality of possible source network addr esses to a plurality of possible ports of 
the switch, whereby a plurality of possible second ports are ca lculated bv using a source 
network address of the packet wherein each one o f the plurality of possible second ports 
has associated therewith a weight, the weight relating to a likelihood that the packet is 
received from the one of the plurality of possible second ports. 



1 1. (Original) The switch of claim 10 wherein the routing database includes a routing 
tree for each one of a plurality of connected switches. 



12. (Original) The switch of claim 10 wherein the routing database includes a plurality of 
link state update packets and a plurality of routing update packets. 

13. (Original) The switch of claim 10 wherein the second port is calculated by examining 
/ one or more routing trees stored in the routing database. 

14. (Previously presented) The switch of claim 10 wherein the second port is calculated 
by examining a source network address of the packet 

15-17 Cancelled 
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1 8. (Original) The switch of claim 10 wherein the spurious network traffic handling 
includes discarding the packet. 

19. (Original) The switch of claim 10 wherein the spurious network traffic handling 
includes generating an alert. 

20. (Currently amended) An internetwork comprising a plurality of switches, each of the 

switches comprising: 

a plurality of ports, each port connected in a communicating relationship with at 

least one of a connected switch and a network; 

a routing database, the routing database containing information relating to the 

internetwork; and 

a processor, the processor configured to compare a first port of the plurality of 
ports through which a packet is received to a second port of the plurality of ports through 
which the packet is expected to be received, the processor further configured to provide 
spurious packet handling upon determining that the first port is different from the second 
por t , and configured to generate an expec ted port table, the expected port table mapping 
each of a plurality of possible source network addresse s to a plurality of possible ports of 
the switch, whereby a plurality of possible second ports are calculated by using a source 
network address of the packet, wherein e ach one of the plurality of possible second ports 
has associated therewith a weight the wei g ht relating to a likelihood that the packet is 
received from the one of the plurality of possible second ports; 

whereby spurious network traffic within the internetwork is detected. 
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